Extension WordPress
Vulnérabilités Read More & Accordion
Cette page rassemble les failles publiées pour Read More & Accordion, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Read More & Accordion
6 fiches
Read More & Accordion <= 3.5.7 – Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
The Read More & Accordion plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.5.7. This is due to the use of esc_sql() without surrounding the…
*-3.5.7
Non indiqué
19/05/2026
Read More & Accordion <= 3.5.7 – Privilege Escalation via importData
The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.7. This is due to the 'RadMoreAjax::importData' function not restricting which database tables can be written to during…
*-3.5.7
Non indiqué
19/05/2026
Read More & Accordion <= 3.5.5.1 – Missing Authorization
The Read More & Accordion plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.5.5.1. This makes it possible for authenticated attackers, with subscriber-level…
*-3.5.5.1
3.5.6
15/12/2025
Read More & Accordion <= 3.4.7 – Cross-Site Request Forgery to Local File Inclusion
The Read More & Accordion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.7. This is due to missing or incorrect nonce validation on the addNewButtons() function. This makes it…
*-3.4.7
3.4.8
04/04/2025
Read More & Accordion <= 3.4.2 – Missing Authorization to Authenticated (Subscriber+) Arbitrary 'Read More' Post Deletion
The Read More & Accordion plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the expmDeleteData() function in all versions up to, and including, 3.4.2. This makes it…
*-3.4.2
3.4.3
12/02/2025
Read More & Accordion <= 3.2.6.1 – Authenticated (Administrator+) PHP Object Injection
The Read More & Accordion plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.2.6.1 via deserialization of untrusted input from admin settings. This allows authenticated attackers, with administrator-level privileges and above,…
*-3.2.6.1
3.2.7
11/09/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.